Cybersecurity leader showcases AI and automation innovations powered by data to transform security operations at OneCon 2024
SentinelOne (NYSE: S), a global leader in AI-powered cybersecurity, unveiled a suite of innovations designed to drive the autonomous Security Operation Center (SOC) revolution. Built on the leading cybersecurity platform Singularity™ by SentinelOne, these innovations enable security leaders to rethink and transform how they respond to emerging threats to significantly reduce risk, accelerate decision making, and free teams to focus on high-impact initiatives.
Presented on the occasion of OneCon 2024, SentinelOne's customer and cybersecurity conference that took place October 15-17 in Las Vegas, are innovations that define new standards for AI, automation and data, making the prospect of the SOC operating in automated mode a reality:
- Singularity Hyperautomation – Code-free automation for security workflows.
- Singularity AI SIEM – Acquisition and synthesis of all data coming from the security ecosystem.
- Purple AI – Automation of alert triage, search and investigations.
- SentinelOne family of Ultraviolet security templates – Large language models (LLMs) and multi-modal models designed for AI use cases in cybersecurity.
“The future of threat detection and response requires the speed, sophistication of hackers, and the challenges facing today's already overburdened SOCs,” said Ric Smith, President, Product, Technology, and Operations at SentinelOne. "Since our inception, SentinelOne has pioneered the use of AI to automate threat response and resolution. Today, we are making the autonomous SOC challenge a reality by leveraging the power of AI and data to provide customers with the speed, intelligence and scale needed to counter the threats of tomorrow."
Singularity Hyperautomation – No-code automation of security workflows
It is a new intelligent automation solution developed to solve customer security problems. It offers over 100 integrations and dozens of ready-made workflows to address the most common IT threats, such as ransomware mitigation, asset compliance monitoring, and responding to suspicious user activity and insider threats. Singularity Hyperautomation offers a no-code, drag-and-drop framework for building custom processes and automating tasks, plus no-code access to any API to leverage data from any IT or security source.
Integrated directly into the SentinelOne platform, Singularity Hyperautomation connects to analytics processes, where automations are intelligently suggested during investigations. Benefit from the platform and Purple AI to automatically generate playbooks based on colleagues' insights, allowing teams to respond faster and more efficiently. Native integration with Singularity's endpoint, cloud, identity and AI SIEM capabilities means that not only can security teams automate threat remediation across multiple attack surfaces, but also that all first-party and third-party data in Singularity is leveraged to respond to incidents with greater context and less complexity.
Singularity AI SIEM – Acquisition and synthesis of data from the entire security ecosystem
Presented to SentinelOne customers and partners at OneCon 2024, Singularity AI SIEM (Security Information and Event Management) is a cloud-native, no-index SIEM that uses AI and automation capabilities to redefine how SOC analysts operate. Powered by the highly scalable Singularity Data Lake with always-on storage, AI SIEM enables real-time discovery of streaming data, dramatically accelerating investigations and response.
Singularity AI SIEM is built on an open ecosystem, capable of capturing structured and raw data not only from SentinelOne endpoint, cloud and identity security solutions, but also from third-party security and IT tools, leveraging the Open Cybersecurity Schema Framework (OCSF) and pre-built integrations. As a result, customers can gain immediate, expanded visibility into their entire business environment and automate workflows across multiple tools.
Additionally, with SIEM AI and Purple AI, security analysts can leverage SentinelOne's AI-driven autonomous capabilities to perform real-time detection, generative AI-assisted search and investigation, and machine-speed protection against emerging threats.
Purple AI by SentinelOne – Automate alert triage, search and investigations
The security analyst Purple AI by SentinelOne has set the standard for generative AI in cybersecurity since its inception. Integrated with all aspects of the Singularity Platform, Purple AI translates security questions into natural language and structured queries, synthesizes event logs and indicators, guides analysts at all levels through complex investigations, and streamlines collaboration with shared investigation notebooks. At OneCon 2024, SentinelOne further raises the bar for generative AI with the introduction of new Purple AI capabilities designed to quickly automate investigations, reduce alert fatigue and anticipate attacks.
The new Purple AI Auto-Alert Triage prioritizes the most important alerts and helps quickly determine which alerts need further investigation. Auto-Alert Triage leverages new Global Alert Analysis to evaluate thousands of similar anonymized alerts to better determine true positives, and surface prioritized “Alerts to Investigate” to reduce alert fatigue and free up security teams time to focus on the most critical tasks that reduce risk.
Purple AI can now also be used to initiate and run searches autonomously to speed up investigations and response. With the new Purple AI Auto-Investigations feature, Purple AI will take priority alerts, automatically populate a list of investigation steps based on the alert in question, autonomously execute the steps, and generate a recommended verdict. Evidence collected during the investigation is saved in an auditable, collaborative Purple AI investigation notebook to significantly reduce investigation and reporting times, giving SOC and incident response teams the advantage of speed and scale in addressing critical threats.
Introducing SentinelOne's family of Ultraviolet security templates
Over the past three years, the costs of large, general-purpose multi-mode models have decreased substantially, while the capacity of these models has increased significantly. For security-related generative AI applications, these models, combined with broad domain knowledge, have proven to be the best approach to creating truly useful security support experiences. However, there are still areas of AI related to cybersecurity where proprietary models will have decisive advantages.
At OneCon 2024, SentinelOne introduced Ultraviolet, SentinelOne's family of LLMs and multi-modal security templates that solve security use cases and better support the workflows needed to significantly reduce operational overhead.
Ultraviolet will integrate the best generic models, specifically focusing on unique areas such as improving detection effectiveness to consider more contexts in real time, and improving efficiency on security issues to enable greater autonomy where better-tuned models remain active and require substantially fewer tokens to reach useful conclusions.






